Security · Sep 15
GitLab CVE-2026-85706 shows why API path handling needs more than one lock
The CVSS 10.0 path traversal flaw is a patch now event, and a reminder that file access boundaries cannot depend on polite inputs.
- Patch self managed GitLab instances to a fixed release before probing becomes your problem.
- Review APIs that turn user supplied paths into file reads, especially commits, archive, and export endpoints.
- Layer path canonicalization, authentication, authorization, and least privilege file access instead of trusting one check.